CVE-2024-8917

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The AnWP Football Leagues plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.16.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

<p>A complete solution for any &#9917; football site. Has a variety of unique features, powerful and flexible. Made with football in mind.</p> <p>&#9193; For other team sports (&#127945; rugby, &#127936; basketball, &#127952; volleyball, &#127951; cricket, &#9918; baseball, &#127954; ice hockey, handball) use my another plugin &#8211; <a href="https://wordpress.org/plugins/sports-leagues/" rel="ugc">Sports Leagues</a></p> <h4>BASIC FEATURES</h4> <p>&#9989; intuitive admin UI<br /> &#9989; knockout, round-robin or even mixed and multistaged Competition supported<br /> &#9989; separate Club squad for every season (with player position, number, status)<br /> &#9989; Match lineups, substitutes, stats, events (goals, cards, substitute, penalty shootout), video, staff, referees<br /> &#9989; automatic Standing calculation (or manual)<br /> &#9989; automatic Player statistic calculation based on Match events (playing time, goals, cards, etc.)<br /> &#9989; initial data import for Clubs and Players with Excel-like spreadsheet<br /> &#9989; custom colors in Standing table (for Clubs or places)<br /> &#9989; flipped countdown timer for upcoming Matches<br /> &#9989; initial points (+ or -) for Clubs in Standing table<br /> &#9989; statistics at Player profile page<br /> &#9989; stadiums with photo, gallery, additional information, map, matches<br /> &#9989; widgets: Clubs, Matches, Cards, Next match, Player, Players (scorers or assistants), Standing table, Birthdays<br /> &#9989; 16 different shortcodes with UI helper in Classic Editor<br /> &#9989; template system (ability to override output layouts in your theme)<br /> &#9989; RTL support<br /> &#9989; works with most themes out of the box<br /> &#9989; fully translatable from the Admin part<br /> &#9989; tons of hooks for developers<br /> &#9989; staff, referees, coaches, stadiums and much more &#8230;</p> <h4>LINKS AND DOCUMENTATION</h4> <p><a href="https://fl-core.anwp.pro/" rel="nofollow ugc">Plugin Demo</a> | <a href="https://anwp.pro/the-most-powerfull-football-soccer-wordpress-plugin/" rel="nofollow ugc">Plugin Overview</a><br /> <a href="https://anwppro.userecho.com/communities/1-football-leagues#module_9" rel="nofollow ugc">Online Documentation</a> | <a href="https://anwppro.userecho.com/knowledge-bases/2/articles/70-start-guide" rel="nofollow ugc">Start Guide</a> | <a href="https://anwppro.userecho.com/knowledge-bases/11-fl-changelog/categories/28-basic-version/articles" rel="nofollow ugc">Extended Changelog</a> | <a href="https://anwppro.userecho.com/knowledge-bases/2-football-leagues/categories/25-shortcodes/articles" rel="nofollow ugc">Available Shortcodes</a></p> <h4>PREMIUM VERSION AVAILABLE</h4> <p>Want more? Football Leagues has also a <a href="https://anwp.pro/football-leagues-premium/" rel="nofollow ugc">Premium Addon</a> with many outstanding and unique features.</p> <p><a href="https://fl-premium.anwp.pro/" rel="nofollow ugc">Premium Demo</a> | <a href="https://footballan.com/" rel="nofollow ugc">Real Website Example</a></p> <h4>PREMIUM FEATURES</h4> <p>&#128310; Live Scores and Match Live Commentary with Events<br /> &#128310; Match Timeline<br /> &#128310; LIVE Search<br /> &#128310; Club match formation<br /> &#128310; Layout Builder (with tabs)<br /> &#128310; Match scoreboard with image background<br /> &#128310; Tournament Bracket<br /> &#128310; Commentary Match section with new events<br /> &#128310; Head to Head matches section in Match<br /> &#128310; import data from external APIs (required a valid subscription)<br /> &#128310; Standing – manual data edit<br /> &#128310; Standing – columns order and visibility<br /> &#128310; Standing – Conference support<br /> &#128310; Standing – more ranking rules<br /> &#128310; Matches Horizontal Scoreboard (shortcode)<br /> &#128310; Competition – matchweeks as slides<br /> &#128310; Results Matrix<br /> &#128310; Standing Arrows – Dynamics of Ranking changes<br /> &#128310; Widget – Next match extended (timer or flipped countdown)<br /> &#128310; Widget – Competition Matchweek slides<br /> &#128310; Widget – Calendar<br /> &#128310; Calendar Slider<br /> &#128310; Card Suspension<br /> &#128310; Transfers<br /> &#128310; <a href="https://anwp.pro/seo-options-in-layout-builder-title-and-description/" rel="nofollow ugc">Dynamic SEO Options</a><br /> &#128310; Send Game Report by Email<br /> &#128310; <a href="https://anwp.pro/docs/football-leagues/pro-features/user-timezone/" rel="nofollow ugc">Automatic User&#8217;s Timezone</a><br /> &#128310; <a href="https://anwp.pro/docs/football-leagues/pro-features/ai-writer/" rel="nofollow ugc">AI Match Reports</a><br /> &#128310; <a href="https://anwp.pro/docs/football-leagues/pro-features/club-history-historical-logos-names/" rel="nofollow ugc">Club History</a> – Historical logos and names<br /> &#128310; <a href="https://anwp.pro/docs/football-leagues/pro-features/entity-links/" rel="nofollow ugc">Entity Links</a> – Custom links for clubs, players, and more<br /> &#128310; Advanced Statistics<br /> &#128310; Charts: Team Default Statistics &amp; Goals per 15 min. interval<br /> &#128310; Player stats section in Club<br /> &#128310; Player &amp; Referee stats panel<br /> &#128310; 24 different shortcodes<br /> &#128310; premium support</p> <p><a href="https://anwp.pro/football-leagues-premium/" rel="nofollow ugc">Find Out more about Premium Version</a><br /> <a href="https://anwp.pro/the-most-powerfull-football-soccer-wordpress-plugin/" rel="nofollow ugc">Plugin Overview</a></p> <h4>Translations included</h4> <ul> <li>English &#8211; default, always included</li> <li>Russian: Русский</li> <li>Polish: Polski (thanks to @forzza)</li> <li>Danish: Denmark (thanks to @cbdk)</li> <li>French: thanks to @belgofoot</li> <li>Italian: thanks to Paolo</li> <li>Slovenian: thanks to Nejc</li> <li>Romanian: thanks to Gabriel</li> <li>German: thanks to Jörg and Sven</li> <li>Greek: thanks to spirossm</li> <li>Spain: thanks to Màxim</li> <li>Brazil (Portuguese): thanks to Marcelo</li> <li>Dutch: thanks to Patrick</li> </ul> <h4>The plugin requires</h4> <blockquote> <p>PHP version 5.6 or greater<br /> WordPress 4.7 or greater<br /> <a href="https://wordpress.org/plugins/cmb2/" title="CMB2" rel="ugc">CMB2 plugin</a></p> </blockquote>
WordPress Plugin DirectoryWordPress Plugin Directory
74.3K